Data processing addendum
Additional data protection terms for business customers whose personal information Emailmetry processes on their behalf.
Version 2026-09-27 · Updated 27 September 2026
This addendum forms part of the Emailmetry Terms of Service for a business customer when Sahelay Pty Ltd (Emailmetry) processes personal information as a processor for that customer. We act as an independent controller of Authorised Users’ account, sign-in, security, billing and audit records, which our privacy policy covers. We act as processor for the customer personal information described in section 2. If this addendum conflicts with the terms on processing of customer personal information, this addendum controls.
1. Scope and instructions
The customer determines the purposes and means of its processing and warrants that it has authority to give us instructions. We process customer personal information only to provide, secure and support the contracted SPF service, on the customer's documented instructions in the order, service configuration and support requests, or where law requires processing. We will tell the customer before processing required by law unless that law forbids notice. We will inform the customer if, in our reasonable view, an instruction infringes applicable data protection law.
2. Processing details
The subject matter is hosted SPF configuration and account administration. Processing lasts for the service term and any necessary return, deletion, backup or legally required retention period. It may include collection, storage, retrieval, validation, updating, support access, disclosure to approved providers and deletion. Processing is continuous during the service term. Data subjects may include the customer’s clients, where a client name or domain identifies an individual, and people named in support requests. Data may include client names, domain names and client assignments, DNS configuration, and personal information in support messages the customer sends to our support inbox. Customers should not submit sensitive personal information or email message contents to the SPF service.
3. Confidentiality and security
We limit access to authorised people under confidentiality duties and use measures appropriate to the risk, including: a required authenticator app code for every portal user; staff access limited to authorised personnel, with staff actions recorded in audit logs; encryption in transit and encryption of the application database at rest; hosting in a single AWS region in the United States (Oregon) with a non-public database; database backups kept for 7 days; application logs kept for 30 days and designed to exclude IP addresses and email addresses; and periodic review of these safeguards. We will maintain a process for handling security incidents and notify the customer without undue delay after becoming aware of a personal data breach affecting customer personal information, with information reasonably available to help the customer meet its duties. We may provide updates as our investigation continues.
4. Subprocessors and transfers
The customer gives general authorisation for subprocessors needed to provide the service. Current provider categories and named providers are described in the privacy policy; application infrastructure uses AWS, identity uses Supabase, service email uses SMTP2GO and support requests are handled in Microsoft 365 and HaloPSA. We will require subprocessors to protect customer personal information under written terms imposing the same data protection obligations as this addendum and remain responsible for their processing on our behalf. We will give at least 14 days’ advance notice of a new or replacement subprocessor by email. The customer may object on reasonable data protection grounds; we will discuss an alternative or permit termination of the affected service with a proportionate refund of unused prepaid fees if no reasonable alternative is available.
Emailmetry is established in Australia. To the extent the customer's transfer of customer personal information to us is restricted by the EU or EEA General Data Protection Regulation, the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914 (EU SCCs) are incorporated into this addendum by reference and apply as follows: Module One applies to Authorised User information the customer discloses to us as a controller, Module Two applies where the customer is a controller of customer personal information and Module Three where it is a processor; the customer is the data exporter and Emailmetry the data importer; clause 7 does not apply; under clause 9, option 2 (general authorisation) applies with the notice described in this section; the optional wording in clause 11 does not apply; under clauses 17 and 18, the EU SCCs are governed by Irish law and disputes are resolved by the courts of Ireland; under clause 13, the competent supervisory authority is the one identified for the data exporter in the Order or, if none is identified, the authority of the EU member state in which the data exporter is established; and Annexes I, II and III are completed by sections 2, 3 and 4 of this addendum and the parties' details in the Order.
To the extent a transfer is restricted by UK data protection law, the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner (version B1.0) is incorporated by reference, with its tables completed by the information above and neither party able to end it under its section 19. To the extent a transfer is restricted by the Swiss Federal Act on Data Protection, the EU SCCs apply with references to the GDPR read as references to that Act and the Swiss Federal Data Protection and Information Commissioner as the competent authority, and data subjects in Switzerland may bring claims in Switzerland. If the EU SCCs conflict with this addendum, the EU SCCs prevail. Onward transfers to subprocessors are made under their own approved transfer mechanisms. Contact support@emailmetry.com for current data locations and subprocessor transfer documentation.
5. Assistance and requests
Taking account of the service and the information available to us, we will reasonably assist the customer with data subject requests, breach notifications, impact assessments and consultations with regulators. If a data subject asks us about information the customer controls, we will direct the request to the customer where we can identify it, unless law requires another response. The customer remains responsible for its own notices, lawful basis, instructions and responses to data subjects.
6. Return, deletion and audit
At the end of the service, we will, at the customer’s choice, return or delete customer personal information within 30 days of the customer’s written instruction, unless law requires retention. Remaining copies in backups expire under their 7-day cycle. The application does not automatically delete every record when a licence expires; billing, security and audit records may remain where necessary and lawful. We will make available information reasonably needed to demonstrate our compliance with this addendum and permit a proportionate audit by the customer or its independent auditor on reasonable notice, subject to confidentiality, security and protection of other customers.
7. Contact
Send instructions, security enquiries, subprocessor objections and data protection requests to support@emailmetry.com. The parties will cooperate in good faith to complete any additional jurisdiction-specific documents that applicable law requires.
Read Terms of Service